Posts Tagged ‘Adobe’

Adobe Code-Signing Certificate Compromised

Wednesday, October 3rd, 2012 | Bruce Morton

Adobe announced they received two malicious utilities signed by a valid Adobe code-signing certificate. The code-signing certificate was compromised though an attack on their code-signing system.

The code-signing certificate will be revoked on October 4, 2012, and will impact all code being signed after July 12, 2012. A supporting security advisory has been issued.

The compromise of the code-signing certificate does not impact Adobe Certified Document Services (CDS) or any root certificate in the CDS system. As such, there is no impact to customers who have purchased CDS signing certificates.

What is a Certified Document and when should you use it?

Wednesday, August 1st, 2012 | Bruce Morton

I found this article on the Adobe Security Matters website, What is a Certified Document and when should you use it? For those who need to certify documents, you may find it interesting.

As a quick summary, it states that here are two frequent use cases for Certified Documents:

  • Publishing files and want the recipients to know that the files really did originate from you and they have not been accidentally or maliciously modified since you published them.
  • Distribution of electronic forms with pre-populated information, and want to make sure recipients are not accidentally or maliciously modifying your form data when returning them to you.

Entrust issues Adobe CDS Signing certificates which will help you meet the Adobe recommendations:

  • Make sure your signing certificate is trusted by your recipient community.
  • When certifying a document, make sure that all certificates from the trust chain are available on the signing system (desktop or server).
  • When publishing a certified document with a digital signature, make sure you are online and able to reach the revocation information published by the certificate authorities.
  • Utilize an RFC3161 based timestamp authority as part of the digital signature process.